2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2756HIGH7.2SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
CVE-2023-31208HIGH8.8Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8...
CVE-2023-2745MEDIUM5.4WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. ...
CVE-2023-2753MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.
CVE-2023-2752MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.
CVE-2023-2469Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-0864MEDIUM4.3Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (...
CVE-2023-0863HIGH8.8Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wal...
CVE-2023-2509MEDIUM6.1A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this ...
CVE-2023-2706HIGH8.1The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to th...
CVE-2023-2608MEDIUM4.3The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL I...
CVE-2023-31847MEDIUM6.5In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source ...
CVE-2023-1764MEDIUM6.5Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (...
CVE-2023-1763MEDIUM6.5Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (...
CVE-2023-31848HIGH8.8davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF).
CVE-2023-30452MEDIUM5.4The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map wi...
CVE-2023-2528HIGH8.8The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in...
CVE-2023-25394HIGH7Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream...
CVE-2023-31679HIGH7.5Incorrect access control in Videogo v6.8.1 allows attackers to access images from other devices via modification of the ...
CVE-2023-31678MEDIUM5.3Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.
CVE-2023-31677HIGH7.5Insecure permissions in luowice 3.5.18 allow attackers to view information for other alarm devices via modification of t...
CVE-2023-31544MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web...
CVE-2023-30281MEDIUM6.5Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3...
CVE-2023-30189CRITICAL9.8Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
CVE-2023-29927MEDIUM4.3Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privilege...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now